Preliminary research
Pass-the-Passkey Family of Attacks
Upcoming Talk: Pass-the-Passkey Family of Attacks at Black Hat USA 26
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
An announcement for a Black Hat USA 26 briefing, not the research itself. It previews a family of attacks the authors liken to Pass-the-Hash and NTLM relay: a major cloud service's passkey implementation vulnerable to what passkeys prevent, past YubiKey signatures stored in cleartext and readable by unprivileged remote users, and impersonation of privileged identities that bypasses phishing-resistant MFA, blamed on mistakes in WebAuthn's 22-step validation.
Record
- Document
- Upcoming Talk: Pass-the-Passkey Family of Attacks at Black Hat USA 26
- Researcher
- Michael Grafnetter and @MGrafnetter
- Published by
- DSInternals
- Date
- Topic
- Identity
In the archive
Related sources
- Pass-the-Passkey Family of Attacks Whitepaper
- Pass-the-Passkey Family of Attacks (Slides) Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Michael Grafnetter and @MGrafnetter, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .